Skip to content

ROPA

GDPR Article 30 Records of Processing (ROPA) Checklist

A ROPA checklist to inventory processing activities, recipients, transfers, and retention for Article 30.

Estimated time
3–8 Weeks
Audience
Privacy and Legal Operations Teams
Last updated

Operational reference for Article 30 records. Controllers and processors have different required fields.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Collect

Phase 2: Complete Fields

Phase 3: Quality

Phase 4: Use

FAQ

Who must keep a ROPA?+

Controllers and processors, with SME exceptions that are narrow—most growing SaaS should keep one.

Must it be public?+

No. It must be provided to the authority on request.

Is a ROPA a DPIA?+

No. ROPA is an inventory. DPIA is a risk analysis for high-risk processing.

Controller vs processor records?+

Article 30(1) vs 30(2) fields differ. SaaS often needs both.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer